Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

231–240 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#231
post #18

Earlier quoted context omitted.

I'm not sure that people are getting 'used' to it. I was talking to a non-techie over the weekend, and although they were aware about Snowden's NSA revelations, they were quite perturbed to think someone could be reading their email. I don't think people have stopped caring, they just feel helpless. This means that normal people may be willing to adopt new protocols (end-to-end encryption), something they wouldn't do…

Nothing in Snowden's leaks suggests that the government has access to your friend's email, let alone is reading it. Stop exaggerating to your non-techie friends.

You must have been folowing a different leak than me.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#232

Earlier quoted context omitted.

"My country, right or wrong; if right, to be kept right; and if wrong, to be set right ." - Carl Schurz Also, by that logic, any H1B worker that refuses to spy on his company on behalf of his country of citizenship would be a traitor. Do you really want that to be the operative ethics when most S.V. companies are made from people from all over the world? Because I certainly do not.

You don't have to be part of it. If you find out that you are part of it then just quit. But by blowing the whistle you endanger thousands of lives, and you think that just because you're some sort of freedom fighter then it's OK. It's not OK. You want to fight the freedom fight? Go work in politics. Don't screw your own country. BTW - I'm not from the US.

> But by blowing the whistle you endanger thousands of lives

Waiting for you to present your concrete evidence backing this claim up.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#233

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

> I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course.

That would be a nice idea, but short living.

Say for an example, we had "free software." Now many say "open source." As long as we are having greed for money or power, nothing is going to change.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#234
post #155

Earlier quoted context omitted.

> US intelligence activities are actively harmful to American commercial interests because they destroy trust, particularly from customers elsewhere in the world. I think, they actively harm US corporations because they fundamentally destroy trust of US citizens too.

Yea but they're still going to buy the products. Foreigners, especially foreign corporations, are the portion of the market whose buying decision is most sensitive towards these issues.

On one hand, I actually do see domestic harms. People are a bit less inclined to use Yahoo, and a bit more inclined to use Apple, because of their different levels of pushback.

I agree, though, that this is a much smaller issue than the loss of foreign sales. Surveillance won't kill US iPhone usage, but it could probably destroy Cisco's foreign markets.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#235
post #176

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

Save it for the MBAs instead, or even as an onboarding requirement along with other training for new management hires. It's not generally the engineers making these decisions. Sometimes it's an active issue and at the end of the day someone must implement something terrible (knowingly or not -- direct a junior engineer to do some complex task with the expectation they'll leave behind security vulnerabilities, just as…

SCU (my alma mater) does require MBA students to pass an ethics course.

https://www.scu.edu/business/mba-degrees/prospective-student...

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#236
post #194

Earlier quoted context omitted.

Engineers do speak up, frequently. For a famous example, see the Challenger disaster. Again, engineers aren't generally the problem. Still disagree?

The NSA don't seem to lack the technical talent to wantonly shit all over the Constitution. Plenty of HN posts laud people for working for the government, the entity which engages in war crimes, torture, and mass surveillance.

They are hurting for it, though.

There are still lots of people willing to join the TAO and the like, but the NSA has been pretty open about struggling to recruit top talent. Not all of that is ethical stuff, they lose people for reasons from salary to drug and felony screens, but some of it is.

Bear in mind that the NSA only needs good talent to compromise systems, not elite talent. They have some elite talent (Stuxnet anyone?), but their domestic work is largely hacking theater. After all, you don't have to covery your tracks like a private hacker if you can just ship out an NSL to bury the matter. Hell, some of their projects involved a lawyer, a bunch of analysts, and no internal talent - they can just ask for what they want.

https://www.cyberscoop.com/nsa-morale-down-keith-alexander-m...

http://www.capitalgazette.com/news/government/ph-ac-cn-nsa-l...

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#237

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.

The ethics course will make you feel better about going to prison.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#239

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

I don't know how common this is in general, but an ethics course was a required part of the engineering core curricula at my school (Case Western Reserve). Ultimately, though, an ethics course isn't going to make people stand up for their ethics. A professional organization along the lines of the American Medical Association (at least in terms of political strength) that stands up for its members and censures those w…

Professional organizations have a lot of other, unintended negative consequences that make me want to stay the heck away from them. Also, nobody guarantees that the professional organizations themselves would be ethical. The AMA lobbies for things that I consider unethical, as a way to keep their leverage. The American Psychological Association was fine and happy with torture. I've seen an architects association let a member amend their copy of signed documents (which I got to court for, and won, because the editing ended up overlapping a little over my signature, and my own copy didn't have the last clause)

Collective action like this demands doing a lot of work to make it difficult to get a job without being a member, and then works on limiting the influx of members: For instance, you'll find that the attempts of a professional developer association in Spain advertises how it'll increase the value of your college degree, and protect you from having to compete with intruders, like those with physics degrees, or that learned programming from an accelerator, or on their own. And professional organizations have to do this kind of thing, because otherwise they lack the power to get anything done.

So no matter how much I personally dislike mass surveillance, I'd not be caught dead supporting the creation of a professional organization. Instead of using force, how about growing the utility of our work so much, everyone knows they can change jobs the next day to a place that doesn't do mass surveillance? If enough great jobs exist, the awful can't retain talent. That's why developers in the US have far better working conditions like in my native Spain, where finding another job is not something you can do in a week.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#240

Earlier quoted context omitted.

I don't know how common this is in general, but an ethics course was a required part of the engineering core curricula at my school (Case Western Reserve). Ultimately, though, an ethics course isn't going to make people stand up for their ethics. A professional organization along the lines of the American Medical Association (at least in terms of political strength) that stands up for its members and censures those w…

> When there are few professional consequences for unethical behavior at the behest of your employer, taking an ethical stand is ineffective and quixotic. You will be fired and another engineer will likely complete the job. I disagree. I've seen this in action where people who were CCIE-level senior network engineers at one of the five largest ISPs in Turkey quit and got new jobs elsewhere (outside of the country) ra…

Having to leave home country, friends, and community is a steep price to pay for ethics. And the dirty work still got done, albeit ineptly. I think you proved my point.

As morgante said below "If you can professionalize a certain set of ethics, you can make it impossible for your employer to find anyone to complete the job."

Post reply on HN